ORC, Purpleline fined GH¢360,000 for breaching cybersecurity regulations

ORC, Purpleline fined GH¢360,000 for breaching cybersecurity regulations

The Cyber Security Authority (CSA) has imposed a total of GH¢360,000 in sanctions on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited for violating provisions of the Cybersecurity Act, 2020 (Act 1038).

The regulator fined the ORC GH¢240,000 for failing to comply with directives requiring it to engage only licensed Cybersecurity Service Providers (CSPs) for services relating to its Critical Information Infrastructure (CII).

Purpleline Solutions Limited was separately fined GH¢120,000 for providing regulated cybersecurity services without first obtaining the required licence from the Authority.

According to a statement issued by the CSA, the ORC was directed on June 15, 2026, to engage only Tier 1 licensed cybersecurity providers to strengthen the security of its critical information infrastructure.

The Authority also instructed the ORC to submit details of its cybersecurity service providers, the terms of reference for its proposed Security Operations Centre and relevant approvals from the Public Procurement Authority.

However, the CSA said the ORC proceeded to contract Purpleline Solutions, despite the company not holding the required cybersecurity licence.

The Authority said the conduct constituted two separate breaches of its directives under Section 92 of the Cybersecurity Act.

As a result, the ORC was fined 10,000 penalty units for each breach, bringing the total penalty to GH¢240,000, and has been directed to comply with the outstanding directives within one month.

The CSA also found that Purpleline had been providing regulated cybersecurity services before obtaining the appropriate licence.

Although the company applied for a Cybersecurity Service Provider licence on July 15, 2026, the Authority said the application was submitted only after it had established that Purpleline had already been engaged by the ORC.

The regulator stressed that submitting an application for a licence does not permit an organisation to begin offering regulated cybersecurity services.

It warned public institutions and designated Critical Information Infrastructure operators to verify both the licensing status and licence category of cybersecurity service providers before awarding contracts.

The Authority also cautioned companies against providing regulated cybersecurity services without first securing the necessary licence.

It said it would continue to enforce the provisions of the Cybersecurity Act against both organisations that engage unlicensed providers and companies that operate without the required authorisation.

The CSA emphasised that cybersecurity licensing is a legal obligation and not merely an administrative requirement.

Screenshot
Screenshot

Leave a Comment

Your email address will not be published. Required fields are marked *